Refactor earlier mutator implementations to use wildcard methodology - Neuvector
Package Merge Request
Package Changes
Omits the serviceAccounts
list in Neuvector automountServiceAccountToken hardening, allowing the mutator to target all SAs via wildcard. This is more robust and better accommodates upstream changes over time.
At the moment, however, this is a simple refactor and there is no change to the original hardening.
Package MR
(Link to Package MR here)
For Issue
Closes https://repo1.dso.mil/big-bang/bigbang/-/issues/1906
Upgrade Notices
N/A
Merge request reports
Activity
added kindenhancement neuvector priority7 statusdoing teamcore/security labels
assigned to @charden
removed statusdoing label
@charden This merge request is not marked as draft, if it is ready for review please add the label, statusreview.
added needs-labels label
removed needs-labels label
added statusreview label
requested review from @ryan.thompson.44, @ryan.j.garcia, @chris.oconnell, and @michaelmartin
@andrewshoell : You have been tagged in this merge request for the purpose of conducting secondary review.
mentioned in commit 4d622bd1